Industroyer

A forum for feature requests/discussions and user submitted patches that improve MQ2

Moderator: MacroQuest Developers

winultimate
orc pawn
orc pawn
Posts: 11
Joined: Fri Apr 28, 2017 2:16 am

Industroyer

Post by winultimate » Thu Jun 15, 2017 10:35 pm

Just today I found out that my compile has this:

https://www.bleepingcomputer.com/news/s ... wer-grids/

And so my Anti-malware removed it, and required reboot of my PC to finish cleaning.

Never seen that happened to a compile that I compiled before.

EqMule
Developer
Developer
Posts: 2697
Joined: Fri Jan 03, 2003 9:57 pm
Contact:

Re: Industroyer

Post by EqMule » Fri Jun 16, 2017 2:13 pm

Send it to them for analysis so they can whitelist it. Don't forget to mention it's open source so they can actually check the source as well.

I suppose it's possible that your version has been infected after you built it.
My status o/
If you like MQ2 and would like to contribute, please do. My goal is 25 donations per month.
So far I've received Image donations for this month's patches.

Bitcoin: 1Aq8ackjQ4f7AUvbUL7BE6oPfT8PmNP4Zq
Krono: PM me.
I can always use characters for testing, PM me if you can donate one.

demonstar55
a snow griffon
a snow griffon
Posts: 314
Joined: Fri Nov 28, 2008 6:31 am

Re: Industroyer

Post by demonstar55 » Fri Jun 16, 2017 2:19 pm

Also, what file did it report as malware?

crawky
decaying skeleton
decaying skeleton
Posts: 3
Joined: Mon Sep 11, 2006 3:27 pm

Re: Industroyer

Post by crawky » Wed Jun 21, 2017 11:26 pm

I had a file flagged by Malwarebytes (version 3.0.6.1469). The file was flaggged as soon as I tried to run MQ2
Threat: Backdoor.Industroyer.Generic
File: MQ2-20170615\RELEASE\MQ2MAIN.DLL

demonstar55
a snow griffon
a snow griffon
Posts: 314
Joined: Fri Nov 28, 2008 6:31 am

Re: Industroyer

Post by demonstar55 » Thu Jun 22, 2017 1:28 am

It's a false positive, report it to them.

winultimate
orc pawn
orc pawn
Posts: 11
Joined: Fri Apr 28, 2017 2:16 am

Re: Industroyer

Post by winultimate » Mon Jun 26, 2017 4:48 pm

What's weird is that after the offending MQ2Main file and its source were removed by the antivirus, the strange power reading for my computer battery is back to 100%. It was at 81% plugging but not charging before the malware was quarantined.

Backdoor.Industroyer.Generic

winultimate
orc pawn
orc pawn
Posts: 11
Joined: Fri Apr 28, 2017 2:16 am

Re: Industroyer

Post by winultimate » Fri Jul 07, 2017 12:01 am

Seems like my comp slows down during this past couple of weeks. But after I removed this malware, and rebooted, the comp is faster now and not bogged down every time running web browsers and folders.

Cilraaz
orc pawn
orc pawn
Posts: 25
Joined: Tue Mar 29, 2016 2:05 pm

Re: Industroyer

Post by Cilraaz » Fri Jul 07, 2017 12:06 am

The placebo effect is a hell of a thing.

User avatar
warlock45
a grimling bloodguard
a grimling bloodguard
Posts: 881
Joined: Sat Oct 06, 2007 8:32 pm

Re: Industroyer

Post by warlock45 » Fri Jul 07, 2017 10:28 pm

MQ is virus free so...

you musta cleared something else =)